Buyer Onboarding
The public integration checklist for connecting an OpenRTB buyer to CloudX.
Use this page to scope an OpenRTB integration before exchanging credentials or test traffic. You provide the buyer endpoint URLs; CloudX configures them and any authentication details privately. The protocol contract stays public here.
Capability matrix
| Area | Public contract |
|---|---|
| Inventory | Mobile in-app inventory. Website, CTV, audio, and other channels are outside this public contract. |
| Display | HTML or MRAID for banner, MREC, interstitial, and rewarded placements. |
| Video | VAST for interstitial and rewarded placements. |
| Native | Native is available for some publisher integrations, but not through the standard buyer endpoint. Contact CloudX to confirm Native support for your integration. |
| App Open | CloudX rendering is endpoint-dependent. Eligible endpoints support fullscreen HTML/MRAID or VAST creatives; CloudX confirms support during onboarding. |
| Protocol | OpenRTB 2.5 or 2.6, configured per endpoint. |
| Regions | Production auction services operate in the United States, Europe, Asia-Pacific, and South America. CloudX confirms the regions enabled for your integration. |
| Transport | HTTPS POST with application/json. Keep connections alive. |
| Authentication | Endpoint-specific, when required. Credentials or static headers are exchanged out of band and never published in this guide. |
| Request shape | One imp per request. The same opportunity can reach your endpoint in multiple auction rounds. |
| Auction integrity | Supported integrations can rank bids inside an isolated, attestable Trusted Execution Environment. Optional TEE features are coordinated during onboarding. |
| Timeout | Read tmax on every request. The default is 1400 ms, but CloudX can configure it per endpoint. |
| Currency | USD CPM only. Non-USD bid responses are rejected. |
| Compression | Uncompressed, gzip, or zstd request bodies by agreement; gzip or zstd responses when advertised. |
| Test traffic | Integration traffic is marked with test: 1. CloudX coordinates controlled test traffic before launch. |
| Privacy | TCF, GPP, US Privacy, GPC, DNT, and LMT signals can affect each request. See Privacy for OpenRTB Buyers. |
| Measurement | Supported SDKs attempt OM SDK measurement for CloudX-rendered HTML and VAST. Confirm certification parity for the shipped SDK version before promising coverage; see Viewability. |
Regional availability does not promise traffic volume, QPS, latency, or an SLA. Confirm commercial and capacity commitments in your agreement.
What CloudX needs from you
Provide these details to your CloudX account manager:
- Production and test HTTPS endpoint URLs
- OpenRTB 2.5 or 2.6
- Supported display and video formats
- Required authentication headers or query parameters
- Whether request bodies should be uncompressed, gzip, or zstd
- Technical and operations contacts
Build against the contract
- Implement the Bid Requests and Bid Responses contracts.
- Apply every privacy signal on the request; never infer consent from the presence of an advertising ID.
- Return HTML/MRAID or VAST that passes the Creative Specification.
- Make
nurl,burl, andlurlhandlers idempotent and tolerant of asynchronous, best-effort delivery. - Verify the publisher path using Supply Transparency.
Launch checklist
- Accept each HTTP request as a separate bid opportunity, even when an earlier round used the same
id. - Respond before the request’s
tmax; return204or an emptyseatbidwhen not bidding. - Echo
bidresponse.idandbid.impid, send one seat with one bid, and bid in USD. - Include a stable
cridand at least one non-emptyadomainon every bid. - Honor
bidfloor,bcat,badv, privacy signals, and your own policy controls. - Validate uncompressed and agreed compressed request bodies.
- Validate every response encoding your endpoint plans to send.
- Render each supported creative type on a real device.
- Confirm expected
nurl,burl, andlurloutcomes without assuming exactly-once delivery. - On CloudX-settled requests, reconcile
app.publisher.id, app-ads.txt, and sellers.json withsource.schainin OpenRTB 2.6 orsource.ext.schainin 2.5. - Complete controlled
test: 1traffic before production enablement.